extractor_setup.exe

Setup Factory 8.0 Runtime

The program is a setup application that uses the Setup Factory installer. The file has been seen being downloaded from theextractor.org and multiple other hosts.
Product:
Setup Factory 8.0 Runtime

Description:
Setup Application

Version:
8.2.2.0

MD5:
fe510c0ab5872e8de42492d809fe7cb6

SHA-1:
97987b9492ae903c535d7cc01584878060a340fc

SHA-256:
b8d35be87d8b7bdee6c02b467e5aad103978c01b2e6e4d6a57b65899dacc9e6b

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/27/2024 7:53:33 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.DownLoader5.58412
9.0.1.076

File size:
1.7 MB (1,759,445 bytes)

Product version:
8.2.2.0

Copyright:
Setup Engine Copyright © 2004-2010 Indigo Rose Corporation

Trademarks:
Setup Factory is a trademark of Indigo Rose Corporation.

Original file name:
suf80_launch.exe

File type:
Executable application (Win32 EXE)

Installer:
Setup Factory

Language:
English (United States)

Common path:
C:\users\{user}\downloads\extractor_setup.exe

File PE Metadata
Compilation timestamp:
6/22/2010 7:31:07 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:P33/TOMs8RVFXqyaNNU3ooYrqrMa1JPzxOXN+eOVbO+ggvDbxsfJlsmo:P3LW8RVtAC3pYrwtOl+g2bCk

Entry address:
0x3079

Entry point:
E8, FB, 2E, 00, 00, E9, 16, FE, FF, FF, 55, 8B, EC, 83, EC, 04, 89, 7D, FC, 8B, 7D, 08, 8B, 4D, 0C, C1, E9, 07, 66, 0F, EF, C0, EB, 08, 8D, A4, 24, 00, 00, 00, 00, 90, 66, 0F, 7F, 07, 66, 0F, 7F, 47, 10, 66, 0F, 7F, 47, 20, 66, 0F, 7F, 47, 30, 66, 0F, 7F, 47, 40, 66, 0F, 7F, 47, 50, 66, 0F, 7F, 47, 60, 66, 0F, 7F, 47, 70, 8D, BF, 80, 00, 00, 00, 49, 75, D0, 8B, 7D, FC, 8B, E5, 5D, C3, 55, 8B, EC, 83, EC, 10, 89, 7D, FC, 8B, 45, 08, 99, 8B, F8, 33, FA, 2B, FA, 83, E7, 0F, 33, FA, 2B, FA, 85, FF, 75, 3C, 8B...
 
[+]

Entropy:
7.9430  (probably packed)

Code size:
32 KB (32,768 bytes)

The file extractor_setup.exe has been discovered within the following program.

The Extractor  by N00bsoft
Publisher's description - “The Extractor the fastest way to unpack zip and rar files. The fast, free and easy way to extract hundreds of compressed zip and rar files with just one click.”
theextractor.org
About 2% of users remove it
 
Powered by Should I Remove It?

The file extractor_setup.exe has been seen being distributed by the following 2 URLs.

Scan extractor_setup.exe - Powered by Reason Core Security